Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims
as part of policy. If using allowed_idp_claims
and a user's claims are changed, Pomerium can make incorrect authorization decisions.
v0.15.6
databroker
service by clearing redis or restarting the in-memory databroker to force claims to be updatedhttps://github.com/pomerium/pomerium/pull/2724
If you have any questions or comments about this advisory: * Open an issue in Pomerium * Email us at security@pomerium.com
{ "nvd_published_at": "2021-11-05T23:15:00Z", "github_reviewed_at": "2021-11-08T21:37:07Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-863" ] }